Files

33 KiB
Raw Permalink Blame History

capsules/MANIFEST.md — Block Ownership Registry (justifications)

StarshipOS / StarForth — Captain Bob (Robert Allan James)

This document is authoritative for WHY each block is where it is and

whether it's immutable. For WHICH blocks exist and their current

content hash, see capsules/BLOCK_MAP.md — auto-generated by

make -f Makefile.starkernel manifest (or on every kernel build),

never hand-edited. If the two ever disagree on a block NUMBER,

BLOCK_MAP.md is correct; this document's numbers need updating.

Any new capsule MUST claim a range and get a justification row here

before first commit. Collisions are marked ⚠️ — resolve before

production bake.


How to Read This Document

Each entry lists:

  • File — path relative to capsules/
  • Blocks — LBN range(s) claimed (cross-check against BLOCK_MAP.md)
  • Immutable — block is locked for life; reason given
  • Justification — why each block or range lives where it does

The block namespace is shared across all loaded capsules. mkcapsule.c bakes every .4th file into the kernel image. If two capsules claim the same block and are loaded together, the later-loaded definition wins in block RAM. Definitions already compiled into the dictionary are unaffected, but LOADing that block again would give wrong results. Flag collisions; resolve before production bake. Run mkcapsule --manifest capsules (or make -f Makefile.starkernel manifest) before adding any new capsule — it reports conflicts directly, no need to hand-check against the tables below.

For the full current block-to-capsule map (LBN, capsule, content hash, conflict status), see capsules/BLOCK_MAP.md — regenerated automatically on every Makefile.starkernel build, so it never drifts. This document intentionally no longer duplicates that map; it only carries the parts a tool can't generate — the justification for each block and the history of how the layout got here.


Mama VM Personality Capsules

Mama VM is the root VM (Hera). Exactly one Mama personality is active at a time. All entries in this section are mutually exclusive — they are never loaded together.

init.4th — Default Mama personality

Blocks: 20492052, 2057

Block Immutable Justification
2049 No Hera VM init: loads compudynamics, VM-INIT, lib, common:msg, fleet-k, process; BIRTHs Artemis + Hermes. VM-TREE + VM-CHILDREN implemented (b52281b9), unrolled for v1 Tripod
2050 No BOOT-BANNER call — separated so the banner block can be swapped without touching init logic
2051 No TRIPOD-TEST — 6 acceptance gates per TRIPOD.md. Dead EVENT-WAIT step replaced with HERMES-TICK liveness check (3436d564)
2052 No TRIPOD-TEST invocation block
2057 No BOOT-BANNER word definition (reusable across Mama variants)

Note: 2048 is the kernel ramdrive entry point. init.4th starts at 2049 intentionally (2048 = PERSONALITY block, loaded separately by the capsule birth protocol).

doe.4th — DoE Mama personality

Blocks: 21002107

Moved from 20492056 (2026-07-05) — that range collided with init.4th's real blocks (20492052). Alternate-personality status doesn't excuse a real LBN clash when both capsules are baked into the same binary; renumbered into the range this doc had already earmarked for doe.4th ("21002199") but the file itself had never actually used. See Conflict Register C2.

Note (2026-07-08): the table below previously described generic lifecycle-stage content ("loop control", "teardown / flush") that didn't match any of this file's actual blocks. Rewritten to match the live file.

Block Immutable Justification
2100 No Factor threshold constants (ENT-HI/CV-HI/TMP-HI/STB-HI) + run-matrix sizing (N-CFG/N-REPS/N-RUNS)
2101 No Serial output primitives: N./COMMA/CRLF/CSV-COL/CSV-LAST/CSV-HEADER
2102 No Factor extraction + apply: CFG-ENT/CFG-CV/CFG-TMP/CFG-STB/APPLY-CFG (drives L8-UPDATE/L8-APPLY)
2103 No DOE-WORK: the arithmetic workload itself (~5000-iteration loop, ~35000 word executions)
2104 No Run matrix: RUN-MATRIX (CREATE...ALLOT) + MATRIX!/MATRIX@/SWAP-MTX/INIT-MATRIX. Not fully immutable: CREATE allocates memory at compile time
2105 No Fisher-Yates shuffle (SHUFFLE-MATRIX) over the run matrix
2106 No EMIT-ROW: CSV row emitter, pulls inference-engine state (INFER-RUN, L8-MODE, WINDOW-DIVERSITY, etc.)
2107 No EXEC-DOE/DOE: main entry point — seeds, shuffles, runs the full matrix, emits CSV

init-4.4th — Mama variant (numbered)

Blocks: 21302132

Block Immutable Justification
2130 No Mama variant init logic
2131 No Variant personality block 2
2132 No Variant personality block 3

init-7.4th — Mama variant (numbered)

Blocks: 2150

Block Immutable Justification
2150 No Single-block Mama variant

init-8.4th — Mama variant (numbered)

Blocks: 2160

Block Immutable Justification
2160 No Single-block Mama variant

init-0.4th — Mama variant (numbered)

Blocks: 22002201

Block Immutable Justification
2200 No Mama variant init
2201 No Mama variant personality continuation

init-6.4th — Full-range Mama variant

Blocks: 20802095

Moved from 20482063 (2026-07-05). That range put both init-6.4th and its byte-identical twin init-l8-omni.4th on top of init.4th's real blocks (20492052, 2057) — a genuine collision the original Conflict Register missed by only tracking "6 vs omni" (C1) and "init vs doe" (C2) as separate entries, never checking omni/6 against init.4th itself. See Conflict Register C1.

Block Immutable Justification
20802095 No Full Mama personality suite: 16 blocks covering init, loop control, L8 hooks, workload dispatch, banner, teardown

init-l8-omni.4th — L8 Jacquard omni Mama variant

Blocks: 20642079

Moved from 20482063 (2026-07-05), for the same reason as init-6.4th above. init-l8-omni.4th is byte-identical to init-6.4th (same content, same xxHash64) — presumably a copy-forward placeholder awaiting real L8 Jacquard omni-mode content that was never written. Given as a separate capsule anyway (rather than deleted) since it's referenced by name elsewhere as the L8-enabled variant; flagging the duplication here for visibility, not resolving it — that's a content decision, not a block numbering one.

Block Immutable Justification
20642079 No L8 Jacquard omni Mama personality; currently identical content to init-6.4th (see note above)

init-5.4th — Raw code capsule (no block format)

Blocks: none (no Block N headers)

init-5.4th defines words inline without FORTH block formatting. It is a raw code capsule compiled directly into the dictionary at load time. It does not claim any LBN slot and cannot be LOADed by number. This is intentional for volatile/chaos workloads where block-structured layout adds no value.


Workload Capsules (44064849)

Exactly one workload capsule is active per DoE run — never co-loaded with another. Moved off 30013060 (2026-07-05): that range was shared verbatim across all 9 workload capsules on the theory that "mutually exclusive, so sharing is fine" — the same reasoning that masked C1/C2 above, and true only in the narrow sense that boot-time compilation reads capsule text straight from the in-memory payload. The write_ramdrive_block re-cache step (so a human can later type N LOAD) goes through the real block subsystem, and 9 capsules pointing at the same LBN for that step meant only the last-loaded one's text was ever recoverable that way — worth cleaning up even though nothing observable broke. See Conflict Register C3.

Each capsule now owns a private, non-overlapping range. The numbered non-L8 workloads keep their original sparse per-phase spacing (still room to add a phase without renumbering); the contiguous L8 workloads keep their original contiguous style, just relocated.

init-1.4th — Non-L8 workload, 4 phases

Blocks: 4406, 4415, 4425, 4435

Block Immutable Justification
4406 No Workload entry point
4415 No Phase 2 workload words
4425 No Phase 3 workload words
4435 No Phase 4 workload words

init-2.4th — Non-L8 workload, 5 phases

Blocks: 4506, 4515, 4525, 4535, 4545

Same sparse slot pattern as init-1.4th, own private hundred-block zone, plus one additional phase block.

init-3.4th — Non-L8 workload, 7 phases

Blocks: 4606, 4615, 4625, 4635, 4645, 4655, 4665

Largest non-L8 workload. Own private hundred-block zone with room for three more phases (4675, 4685, 4695) before needing a new zone.

init-9.4th — Non-L8 workload, 5 phases

Blocks: 4706, 4715, 4725, 4735, 4745

Structurally identical slot pattern to init-2.4th; different workload content.

init-l8-stable.4th — L8 stable mode workload

Blocks: 4806

Single-block workload. Stable mode = low CV, minimal variability. One block suffices.

init-l8-volatile.4th — L8 volatile mode workload

Blocks: 48104813

Four blocks. Volatile mode generates high-CV execution patterns requiring more definition space.

init-l8-diverse.4th — L8 diverse mode workload

Blocks: 48204822

Three blocks. Diverse mode cycles across word categories.

init-l8-temporal.4th — L8 temporal mode workload

Blocks: 48304831

Two blocks. Temporal mode generates time-varying access patterns.

init-l8-transition.4th — L8 transition mode workload

Blocks: 48404842

Three blocks. Transition mode exercises mode-switching boundary behavior.


Infrastructure Capsules (4000+)

Infrastructure capsules are permanent system libraries. Multiple may be loaded simultaneously. Block assignments in this range are non-overlapping except where explicitly flagged.

Everything in this range lives on Artemis's disk, not the ramdrive. The kernel ramdrive is exactly 1024 blocks, LBN 20483071 (KRD_MAX_BLOCKS in capsule_loader.c). Artemis's virtio-blk disk is attached immediately after as the next device in the block subsystem's LBN-ordered slot chain (kernel_main.c, blk_subsys_attach_device), starting at LBN 3072 — which is also ART-HDR-LBN, the very first byte of Artemis's own on-disk header. So every block number in this section (4000+) resolves through blk_get_buffer()'s device routing to Artemis's persistent disk image (disk/artemis.img), not a scratch buffer. This has been true since these capsules were first numbered — it isn't new. It's provably harmless for boot correctness (capsule_load_blocks compiles word definitions straight from the in-memory payload; the block-subsystem write is only a courtesy copy so a human can later type N LOAD interactively), but it does mean every boot writes capsule source text over whatever LBNs 4000+ map to on Artemis's disk — which is why disk/artemis.img shows a binary diff after every acceptance run. Keep this in mind before claiming new blocks in the "OPEN"/"UNASSIGNED" ranges below: they are disk offsets, not free RAM.

ACL.4th — Word-level ACL system

Blocks: 40004007, 4015

Note (2026-07-08): rows 40014007 below were previously wrong in every row (describing ACL-BOOT-STRICT/ACL-BOOT-PERMISSIVE/ACL-PERMISSIVE-MODE/ ACL-TTL-TICK — none of which exist — and misplacing content between rows, e.g. claiming zuse.4th loads from 4007 when that call is actually in 4015). Corrected this pass by reading the live file directly.

Block Immutable Justification
4000 Yes ACL-STRICT-MODE/ACL-TTL-MODE-VAL/ACL-BASE-TTL/ACL-MAX-TTL constants. Immutable: changing these alters security semantics of all downstream capsules
4001 No ACL-ENTRY ( xt -- xt ): identity word for API symmetry. Not immutable: cosmetic, safe to extend
4002 Yes ACL-STRICT / ACL-TTL-MODE: pin-guarded mode selector words. Immutable: mode selection is a load-bearing policy operation
4003 Yes ACL-TTL-COMPUTE: adaptive TTL formula (heat/4 + ACL-BASE-TTL, capped at ACL-MAX-TTL). Immutable: formally verified in ACL_TTL_Bounded.thy; core enforcement math
4004 Yes ACL-RECHECK: cold-path policy called by C acl_recheck() at TTL=0. Immutable: core enforcement path; changes here affect every word execution under ACL
4005 Yes ACL-BOOT: stamps default ACL via ACL-INIT-PRIMITIVES, pins EXEC/BYE/ACL-RECHECK/ACL-INIT-PRIMITIVES, self-pins. Immutable: self-activation runs once at boot; must be stable
4006 Yes ACL-CA-KEY-LO/ACL-CA-KEY-HI: Ed25519 CA root public key placeholders. Immutable: capsule hash is the root-of-trust fingerprint; any change rejects the birth protocol
4007 No Self-activation placeholder comment + historical note on the removed RWT mechanism (see 40084014 below). Not immutable: comment-only content
40084014 UNASSIGNED. Formerly the "ACL Rolling Window of Truth" (RWT) TTL mechanism (ring buffer, slope inference, ACL-RECHECK-RW, ACL-BOOT-RW). Removed 2026-07-08: it was dead code from the day it was written — the C hot path's acl_recheck() looks up the word literally named ACL-RECHECK (11 chars), never ACL-RECHECK-RW (14 chars), so nothing ever reached this mechanism regardless of ACL-BOOT-RW pinning it. It was never covered by ACL_TTL_Bounded.thy despite this table's prior claim otherwise. Also removed: 4 backing DictEntry fields (acl_rwt[8]/acl_rwt_head/acl_rwt_count/acl_rwt_slope) that violated the project's own four-field ACL limit, and 6 orphaned C primitives (ACL-RWT-*) in src/word_source/acl_words.c.
4015 Yes Self-activation: runs ACL-BOOT (the real, live boot function defined at 4005), then S" zuse.4th" EXEC. Immutable: runs once at boot

zuse.4th — Bootstrap superuser

Blocks: 40164018

Block Immutable Justification
4016 Yes ZUSE-CERT-LO / ZUSE-CERT-HI constants. Immutable: capsule hash = root of superuser trust; changing breaks PKI chain
4017 Yes ACL-ZUSE-BOOT: authenticates session + pins zuse words. Immutable: this is the sole path to zuse_session=1; must not be alterable post-boot
4018 Yes Self-activation (ACL-ZUSE-BOOT). Immutable: runs once at boot

lib.4th — Shared serial output + FORTH aliases

Blocks: 4050

Block Immutable Justification
4050 No N. COMMA CRLF CSV-COL CSV-LAST Q.SHOW USE RUN. Not immutable: these are utilities; adding words is safe. Removing or renaming existing words requires audit of all callers

common/msg.4th — Hermes participant interface

Blocks: 4055

Block Immutable Justification
4055 Yes HERMES-ACK / HERMES-NACK. Immutable: this is the cross-VM ACK/NACK ABI. Every messaging VM (Hera, Hermes, Artemis) loads this at birth. Changing the block or the word names breaks the Hermes delivery protocol

doe-campaign.4th — DoE campaign harness

Blocks: 40604065

Note (2026-07-08): this table previously described fictional content (e.g. "CSV output formatting", "statistical reduction words") that never matched the file at any point on record. Rewritten to match the actual content, migrated this pass off the deleted compudynamics.4th/ fleet-k.4th primitives onto the VM-PHYSICS-STATUS/VM-CONSERVED? mechanism — see capsules/hermes/init.4th block 4153 and capsules/artemis/init.4th block 4852 for the companion LOAD-DOE fix this migration also required.

Block Immutable Justification
4060 No SETUP-HERMES/SETUP-ARTEMIS/SETUP-VMS: BIRTH + remote LOAD-DOE VM-EXEC per child VM. Not immutable: setup sequence may grow
4061 No PHASE1-DOE: real per-VM DOE-WORK baseline touches. Historical note: dead CD-WORK (index-dispatch, deleted VM-HERA/HERMES/ARTEMIS constants) removed here 2026-07-08
4062 No CD-TICK/CD-DOE: one real fleet-touch pass (VM-EXEC "DOE-WORK" on Hermes+Artemis), looped N times. CAMPAIGN-STATUS: VM-PHYSICS-STATUS + VM-CONSERVED? check. Not immutable: workload/status content may evolve
4063 No CAMPAIGN: full campaign — baselines then 30 real fleet touches
4064 No SMOKE-CAMPAIGN: 1-rep seed-1959 smoke test + 16 real fleet touches
4065 No THREE-VM-CAMPAIGN: loads doe.4th locally on Hera, then 48 real fleet touches, all three VMs as Compudynamics peers

hermes/init.4th — Hermes VM (messenger)

Blocks: 41004109, 41144121, 41424153

Gap 41104113 = Artemis. HARD LOCKED. Never touch from Hermes side. Gap 41224141 = Artemis (extended — see below). Never touch from Hermes side.

Block Immutable Justification
4100 Yes Hermes constants: event codes, channel states, node sizes, arena sizes, MSG-DELIVERED. Immutable: changing node size constants corrupts all arena math
4101 Yes Arena CREATE: MSG-ARENA CH-ARENA MBR-ARENA; free-list roots; MSG-SEQ CH-ACTIVE. Immutable: CREATE allocates memory at compile time; re-running changes VM memory layout
4102 Yes MSG-INIT-FREE + CH-INIT-FREE. Immutable: free-list init is called once from CD-INIT; structure change breaks allocator
4103 Yes MBR-INIT-FREE + MSG-ALLOC + MSG-FREE-NODE. Immutable: allocator ABI; MSG-ALLOC is called by every MSG-SEND
4104 Yes CH-ALLOC + CH-FREE-NODE + MBR-ALLOC + MBR-FREE-NODE. Immutable: same allocator ABI constraint
4105 Yes Message field accessors (MSG-TYPE@/! through MSG-SEQ@/!). Immutable: field offsets are load-bearing; changing breaks every accessor caller
4106 Yes Channel + member accessors (CH-ID@/! through MBR-VM@). Immutable: same field offset constraint
4107 No VARIABLE MSG-LAST-MSG + IDX>NAME + MSG-DELIVER. Not fully immutable: MSG-DELIVER may evolve for async model. IDX>NAME now a table lookup over VM-NAME-ADDRS/LENS (see 4142)
4108 No MSG-SEND. Not immutable: send protocol may evolve
4109 No MSG-REAP. Ordering bug fixed (8ca0cda2) — type cleared before free-node prepend
41104113: ARTEMIS. NEVER TOUCH.
4114 No VARIABLE CH-SCAN + CH-COOL-ALL + CH-TOTAL-HEAT. Not immutable: channel cooling may evolve
4115 No CH-REAP-SAFE. Not immutable: channel reaping logic may evolve
4116 No VARIABLE COMMON-CH + COMMON-INIT + HERMES-TICK. Not immutable: HERMES-TICK drives the event loop; may grow
4117 No EVENT-EMIT + EVENT-WAIT + EVENT-DRAIN (backward compat). Not immutable: EVENT-WAIT is a diagnostic peek only per HERMES.md
4118: reserved, currently empty (former HERA-NOTIFY-SPAWN/KILL, removed 9323f776 — notification is automatic via vm_physics_init/retire)
4119 No CH-MINT-ID + CH-REQUEST. Not immutable: channel negotiation protocol may expand (multi-party invite deferred)
4120 No CD-INIT. Not immutable: init sequence may grow
4121 No MSG-ACK-LAST + MSG-NACK-LAST. Not immutable: NACK-requeue (reduced heat, retry) deferred; block may need extension
41224141: ARTEMIS (extended). NEVER TOUCH.
4142 No VM name routing table: VM-NAME-ADDRS/LENS + VM-NAME-REG + VM-NAMES-INIT. Not immutable: table-driven, grows via VM-MAX
4143 Yes MSG-CH@/! + MSG-ORIG-TYPE@/! + MSG-NACKED. Immutable: field offset constraint, same as 4105
4144 No MSG-SEND. Not immutable: send protocol may evolve
4145 No MSG-TOTAL-HEAT + MSG-REDELIVER-NACKED. Not immutable: cooling/redelivery logic may evolve
4146 No MSG-DELIVER-ALL. Not immutable: delivery logic may evolve
4147 No HERMES-K + WELCOME. Not immutable: may grow
4148 No CH-ACCEPT + CH-CONFIRM + CH-CLOSE. Not immutable: channel negotiation protocol may expand
4149 No HERMES-STATUS (MSG-USED + CH-USED). Not immutable: status may expand
4150 No Member management: MBR-NEXT!/VM! + CH-ADD-MBR + HERMES-MSG-TEST. Not immutable: may grow
4151 No Phase 2 real multi-member broadcast: MSG-BROADCAST + BC-* variables. Not immutable: broadcast protocol may expand
4152 No Phase 2 COMMON-CH membership + test: BCAST-GOT/BCAST-RECV/REGISTER-COMMON-MEMBERS/SEND-BROADCAST-TEST. Not immutable: test harness may grow
4153 No LOAD-DOE ( -- ): S" doe.4th" EXEC. Added 2026-07-08 — doe-campaign.4th's SETUP-HERMES calls this remotely so Hermes gets DOE-WORK; was missing entirely before this pass, so doe-campaign.4th could never have worked even pre-dating the VM-fleet-physics redesign. Not immutable: trivial wrapper

2026-07-05 collision fix: blocks 41424150 were previously numbered 41224131 (interleaved with the blocks below them in this list), directly colliding with Artemis's real block range. The collision was introduced fca7b09a (Jul 1) when the VM-name routing table was added without checking MANIFEST.md, and went undetected for 4 days because mkcapsule's build path doesn't run conflict detection (only --manifest does). Found via mkcapsule --manifest while syncing this document; renumbered into genuinely free space and reverified with a clean amd64 TRIPOD-TEST boot (PASS: fleet K, PASS: Hermes liveness, PASS: Artemis ready, K soak, PASS: E2E msg flow — Hermes's kill/rebirth soak test reproduced an identical dict_hash before and after, confirming the reload path is now clean). amd64-only per the rev-f iteration rule; three-arch not yet run for this fix. See Conflict Register entry C5.

artemis/init.4th — Artemis VM (flat pool disk manager v2)

Blocks: 41104113 (core, hard locked) + 41224141, 48514852 (extended)

HARD LOCKED (41104113). Core Artemis block storage primitives. They live in the middle of the Hermes range by deliberate layout choice (Hermes owns 41004121 + 41424150; Artemis owns 41104113 as a protected island plus its own extended range at 41224141). No other capsule may ever claim these blocks. No tool, script, or automated process may modify these blocks without Captain Bob's explicit written permission.

Artemis's extended range grew organically across several sessions (ed05db25 Artemis BAM, 48b5f726 entry-block renumbering) without a MANIFEST.md update at each step — this is the range that collided with Hermes (see above). The table below reflects the actual current footprint.

Block Immutable Justification
4110 Yes Constants (ART-HDR-LBN, ART-FM-LBN, ART-DATA-LBN, ART-DATA-BLKS) + Q-DECAY. Immutable: constants define the on-disk geometry; changing them corrupts existing disk images
4111 Yes LE32!/LE32@ — arch-neutral little-endian 32-bit byte I/O. Immutable: on-disk format depends on these; changing byte order corrupts cross-arch images
4112 Yes SHL1N/SHR1N/BIT-TEST/BIT-SET/BIT-CLR — bit manipulation. Immutable: free map correctness depends on these primitives
4113 Yes FM-ADDR-BIT/FM-TEST/FM-SET/FM-CLR — free map core. Immutable: free map ABI; changing breaks allocator
4122 No FM-FIND-FREE/BLK-ALLOC/BLK-FREE. Not immutable: scan strategy may improve (e.g. hint-based)
4123 No ART-MAGIC!/ART-MAGIC? — disk detection primitives. Not immutable: magic check may extend
4124 No ART-BOOT-DETECT/BLK-FETCH/BLK-PERSIST/ART-FLUSH. Not immutable: boot mode may gain additional cases
4125 No ART-HDR-WRITE — on-disk header format. Not immutable: header layout may extend
4126 No ART-FORMAT/ART-RESUME/ART-HALT-UNRECOG. Not immutable: resume path will grow
4127 No ART-STATUS/WELCOME. Not immutable: status may expand
4128 Yes LE64!/LE64@ — depends on LE32!/LE32@ (4111). Immutable: same on-disk format constraint
4129 UNASSIGNED (former entry block; entry moved to 4133 in 48b5f726)
4130 No ART-BLANK? — blank block detection. Not immutable: may extend
4131 No ART-INIT — boot state machine. Not immutable: boot cases may grow
4132 No ART-SELF-TEST. Not immutable: may expand
4133 No Entry block — ART-INIT ART-BOOT-ENTRY WELCOME. Numbered after all defs to avoid CAPSULE DEFER; may grow
4134 No ART-WRITE-TEST (persist-write test). Not immutable: test may expand
4135 No ART-READ-TEST (persist-read test). Not immutable: test may expand
4136 No ART-BOOT-ENTRY — boot-mode dispatch. Not immutable: dispatch cases may grow
4137 Yes BLK-HEAT arena (CREATE ... ALLOT). Immutable: CREATE allocates memory at compile time; re-running changes VM memory layout
4138 No BLK-HEAT@/! + LBN>IDX. Not immutable: accessor logic may evolve
4139 No ART-K-TOTAL + ART-COOL. Not immutable: cooling logic may evolve
4140 No ART-REAP + ART-TICK. Not immutable: reap logic may evolve
4141 No CD-INIT — Hera calls this at fleet boot. Not immutable: init sequence may grow
4851 No ART-PING ( -- ): cheap O(1) touch target for Phase 3 fleet DoE workload, unlike ART-TICK/ART-STATUS which scan all ART-DATA-BLKS. Not immutable: may extend
4852 No LOAD-DOE ( -- ): S" doe.4th" EXEC. Added 2026-07-08 — same missing-word fix as hermes/init.4th 4153; doe-campaign.4th's SETUP-ARTEMIS calls this remotely. Not immutable: trivial wrapper

process.4th — VM process management

Blocks: 43004301

Block Immutable Justification
4300 No Event code constants + SPAWN + PAUSE lifecycle operators. Not immutable: process model may evolve
4301 No RESUME + KILL-VM. Not immutable: process model may evolve

Deleted capsules (historical)

compudynamics.4th (formerly 42004204) and fleet-k.4th (formerly 44004405) were deleted in 9323f776 (2026-07-05) — superseded by the generalized VM fleet physics mechanism (capsule_vm_physics.c/.h, VM-CONSERVED? / VM-PHYSICS-STATUS primitives). See docs/working/architecture/VM-PHYSICS-DYNAMIC-FLEET-DESIGN-20260705.md and docs/working/archive/session-logs/2026-07-05-worklog.md. Their former ranges are now UNASSIGNED (see Namespace Map).


Unassigned Ranges

Range Status Notes
02047 KERNEL VM internal; never use in capsules
20532056, 20582063 UNASSIGNED init.4th extension space (after its real 20492052,2057)
20962099 UNASSIGNED Between init-6.4th and doe.4th
21082129 UNASSIGNED doe.4th extension space (within its 21002199 range)
21332149 UNASSIGNED Between init-4 and init-7 variants
21512159 UNASSIGNED Between init-7 and init-8 variants
21612199 UNASSIGNED Between init-8 and init-0 variants
22022999 UNASSIGNED Open for future Mama variants
30013999 UNASSIGNED Freed by the 2026-07-05 workload renumbering (was 30013060, shared across all 9 workload capsules — see C3). NOTE: LBN 3072+ is Artemis's virtio-blk disk, not ramdrive — see the callout above the Infrastructure Capsules section before claiming anything here
40084009 UNASSIGNED ACL extension space
40194049 UNASSIGNED ACL / zuse extension space
40514054 UNASSIGNED lib.4th extension space
40564059 UNASSIGNED common:msg extension space
40664099 UNASSIGNED doe-campaign extension space
41544199 UNASSIGNED Hermes extension space (post-4153)
42004299 UNASSIGNED Former compudynamics.4th range (deleted 9323f776)
43024399 UNASSIGNED process extension space
44004405 UNASSIGNED Former fleet-k.4th range (deleted 9323f776)
44104414, 44204424, 44304434 UNASSIGNED init-1.4th's private zone, room for growth
4853+ OPEN Future capsules — claim here first

Conflict Register

ID Blocks Capsule A Capsule B Risk Resolution
C1 20482063 init-6.4th init-l8-omni.4th / init.4th Resolved (was mislabeled Low — the pair also silently overlapped init.4th's real blocks, missed because the register only tracked "6 vs omni") init-l8-omni.4th moved to 20642079; init-6.4th moved to 20802095. Both now clear of init.4th (20492052,2057) and of each other.
C2 20492056 init.4th doe.4th Resolved (was real — both baked into the same binary; "never co-loaded" doesn't stop a shared-manifest ambiguity) doe.4th moved to 21002107, the range this doc had already earmarked for it but the file never actually used.
C3 30013060 init-1..3,9 init-l8-*.4th Resolved (was real for the N LOAD re-cache path — see the disk-routing callout above the Infrastructure Capsules section; harmless for boot compilation, still worth fixing) Each of the 9 workload capsules moved to its own private range in 44064842; sparse per-phase spacing preserved for the numbered non-L8 workloads.
C4 40104012 ACL.4th zuse.4th Resolved zuse.4th moved to 40164018; no overlap
C5 41224128,41304131 hermes/init.4th artemis/init.4th Resolved (was real — both VMs co-loaded every boot, unlike C1C3's mutually-exclusive personalities) Introduced fca7b09a (Jul 1), undetected for 4 days — mkcapsule's build path runs no conflict check, only --manifest does. Found while syncing this doc. Hermes's colliding blocks renumbered to 41424150; Artemis untouched. Reverified with a clean amd64 TRIPOD-TEST boot, including Hermes kill/rebirth reproducing an identical dict_hash before and after.

mkcapsule --manifest capsules reports zero conflicts as of this renumbering (2026-07-05) — verify with the same command before adding any new capsule.


This document is authoritative for capsule block assignments. Last updated: 2026-07-05 — C1/C2/C3 resolved: eliminated every remaining documented "safe by design" overlap, not just the real C5 one. init-6.4th and init-l8-omni.4th (byte-identical) moved off init.4th's range; doe.4th moved into its own already-documented 21002199 range; all 9 workload capsules moved off the shared 30013060 range into private zones at 44064842. Added a callout that LBN 3072+ (everything infrastructure capsules and workload capsules now occupy) is Artemis's virtio-blk disk, not a ramdrive — discovered while sizing free space for this renumbering. Reverified with a full three-arch (amd64/aarch64/riscv64) TRIPOD-TEST boot: zero FAIL lines, matching dict_hash at every checkpoint on all three architectures, identical to the pre-renumbering baseline (the moved capsules aren't in the default Tripod boot path).

Doc-debt pass, 2026-07-08 — every block-table row was checked directly against the live .4th files and mkcapsule --manifest's authoritative block map (not against this document's own prior claims). Corrected: ACL.4th's entire 40014007 table (every row previously described words that don't exist, e.g. ACL-BOOT-STRICT); doe-campaign.4th's entire table (previously fictional, e.g. "CSV output formatting" — real content is SETUP-VMS/CD-TICK/CAMPAIGN, migrated this same pass off the deleted compudynamics.4th/fleet-k.4th primitives); doe.4th's entire table (block-shifted against real content); missing hermes/init.4th blocks 41514153 and artemis/init.4th blocks 48514852 (both existed in source, undocumented, before this pass — 4153/4852 are new LOAD-DOE definitions added this session to fix a second bug found while migrating doe-campaign.4th: it was never defined on either VM). Zero conflicts per mkcapsule --manifest capsules; three-arch QEMU acceptance run for the doe-campaign.4th/hermes/artemis changes (commit e2f30bfe) before this doc pass. Not re-verified this pass: whether every other still-unflagged row elsewhere in this document matches source exactly — this was a targeted correction of the rows touched by recent work plus doe.4th/ACL.4th, not a full line-by-line re-audit of all ~250 blocks.